Introducing Wiz for Exposure Management: Unify, prioritize, and remediate exposures everywhere.

CVE-2025-25012
Kibana vulnerability analysis and mitigation

Overview

A security vulnerability identified as CVE-2025-25012 was discovered in Kibana, affecting versions up to and including 7.17.28, 8.0.0 up to 8.17.7, 8.18.0 up to 8.18.2, and 9.0.0 up to 9.0.2. The vulnerability is classified as an Open Redirect flaw that could allow attackers to redirect users to arbitrary sites and perform server-side request forgery through specially crafted URLs (Elastic Discussion).

Technical details

The vulnerability is an URL redirection to an untrusted site (Open Redirect) that affects Kibana installations making use of Short URLs within the Discover, Dashboard, and Visualization Library features. The severity is rated as Medium with a CVSS v3.1 score of 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N) (Elastic Discussion).

Impact

The vulnerability can lead to users being redirected to malicious websites and potential server-side request forgery attacks. This affects organizations using Kibana's Short URL features in their Discover, Dashboard, and Visualization Library components (Elastic Discussion).

Mitigation and workarounds

Elastic has released patched versions 7.17.29, 8.17.8, 8.18.3, and 9.0.3 to address this vulnerability. For users unable to upgrade, administrators should restrict access to Kibana features that grant the ability to generate Short URLs. Organizations with Gold, Platinum, or Enterprise licenses can use sub-feature privileges to restrict short-url creation while maintaining read/write access to other features (Elastic Discussion).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management